AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-10868

HIGH · CVSS 7.5 EPSS 1.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-10868
Severity
HIGH
CVSS
7.5
EPSS
1.10%

Original NVD Description

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.